Home · Wiki · Vulnerabilities & CVEs
type: cve · created: 2026-09-23 · updated: 2026-09-23 · tags: [cve] · confidence: high · severity: high · affected_sectors: [technology, government] · au_impact: false

CVE-2025-33053

Summary

A remote code execution flaw in Windows WebDAV scored CVSS 8.8, observed in campaigns that lured users to attacker WebDAV shares.

Details

The digest recorded it inside a wider WebDAV malware campaign: one live operation targeted Windows users in Mexico through a fake government ID-lookup site and exploited CVE-2025-33053 to run its payload. WebDAV is a useful delivery path precisely because Windows resolves \\host\share paths natively, so a link or shortcut can reach the attacker's share without a download prompt — the same property that makes .library-ms and search-connector files recurring phishing artefacts. Mitigation that does not depend on the patch is to block WebClient from starting as a service on hosts that do not use WebDAV.

Attribute Detail
CVE CVE-2025-33053
CVSS 8.8
Vendor / product Microsoft Windows (WebDAV)
Reported in the digest 2026-07-21

Related Pages

Sources: raw/digests/Cyber-Digest-2026-07-21.md